| ▲ | teravor 5 hours ago |
| ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though. |
|
| ▲ | eru 5 hours ago | parent | next [-] |
| What kind of auction would you like to run? Remember that you can sell the same vulnerability to multiple people: it's software you can copy. |
| |
| ▲ | Barbing 5 hours ago | parent [-] | | Maybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.) $1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?). Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough. |
|
|
| ▲ | 27183 5 hours ago | parent | prev [-] |
| it seems unlikely google's lawyers would go for this |
| |
| ▲ | aeonik 5 hours ago | parent | next [-] | | Maybe some code is so important and heavily trafficked it becomes a public works project, and various legs can bid for pieces of the project, line how all infrastructure works. | |
| ▲ | teravor 5 hours ago | parent | prev [-] | | well that's why setting it up is hard, because you would want to do it in a way that what they want doesn't matter. |
|